The threat hiding in your hiring process: how fake remote workers get in
by Claudiu Hulea · IT Management Consultant
Remote hiring is normal and good — we use it too. But it has a failure mode most companies don’t address: someone can pass your entire hiring process without being who they claim to be. This isn’t theory. It’s a scheme documented by the FBI and the US Department of Justice (DOJ), with dozens of raids, convictions and hundreds of infiltrated organisations. Below: how it works and how to defend against it without turning every remote candidate into a suspect.
In brief
- The threat: people obtain remote jobs with fake or stolen identities, hiding who and where they are. The most documented case: North Korean IT workers, who funnel their salaries to the sanctioned regime and sometimes steal data or extort the employer (per DOJ and FBI).
- The scale: a single operation infiltrated more than 300 US organisations; thousands of such workers are estimated to have been placed at US and European companies. The FBI has run raids across multiple states and seized websites and “laptop farms”.
- How they succeed: forged documents, AI-generated / deepfake profiles, VPN + remote desktop to mask location, payments through third parties or crypto, and local facilitators who host the work laptop.
- Why they pass: classic controls tick documents and steps, not the human behind the credentials.
- Defence isn’t paranoia: verify the human, not just the documents; control the equipment logistics; and monitor after the hire, not only at onboarding.
How the scheme works
The core idea is simple, and that’s why it works: each hiring check validates an artefact — a document, a step — not the real person who will use the account.
- Fake or stolen identity. Forged documents or real stolen identities, sometimes of people who don’t know they’re being used.
- An AI-built façade. Generated LinkedIn and social profiles, photos, and increasingly deepfakes in the video interview.
- Location masking. VPN and remote desktop software so the activity looks local, while the operator is in another country.
- Money routing. The salary reaches its destination through third parties, crypto or transfers that break the direct link to the “hired” person.
- Facilitators and “laptop farms”. An accomplice in the employer’s country receives the work laptop and keeps remote access open for the operator abroad — so “equipment delivery” appears confirmed at a local address.
The primary goal, in the North Korean case, is revenue for a sanctioned regime. But once inside, with legitimate access, some move on to code and data theft or extortion with the stolen material.
Why they pass classic controls
A typical hiring process checks: the documents, a background check, confirmation the laptop was delivered. Each step can be satisfied individually by a well-prepared impostor — the document is “valid”, the check passes on a stolen identity, the laptop really was delivered (to a facilitator). None of them confirms that the person behind the account is the one on the documents. The scheme operates in exactly that gap between steps.
What it means for a financial institution
For an ordinary employer, a fake worker is a fraud and data-leak problem. For a regulated financial institution, it’s more: an actor possibly tied to a sanctioned regime, holding legitimate credentials inside the perimeter. That stacks three risks at once — insider, data exfiltration and sanctions/compliance — and it’s exactly the kind of case where HR, security and compliance can no longer each look only at their own piece.
Signs to watch
No single signal is proof, but several together warrant a check (indicators reported in the documented cases):
- Frequent changes to registered details (address, bank account, contact).
- A mismatch between the account name and the payment name.
- Multiple employee accounts accessed from the same IP.
- A single account accessed from many different IPs.
- Unusual login hours, consistently outside the declared timezone.
- Reluctance to turn the camera on, to do spontaneous video interviews, or to submit to live checks.
Our recommendations
Effective defence isn’t “more suspicion” — it’s verifying the human, not just the documents — and continuing that past day one:
- Verify the person, not just the document. A video interview with liveness verification, matching the live identity against the documents. Treat it as a layer, not a one-off onboarding tick.
- Control the equipment logistics. Where is the laptop shipped? An address that doesn’t tie to the candidate, or one reused across “employees”, is a classic facilitator signal. Verify the address and require presence.
- Monitor after the hire. Unauthorised remote-access tools, abnormal login hours, one account from many IPs (or many accounts from one IP), account name ≠ payment name. Onboarding is the moment, not the whole film.
- Least privilege and segmentation. A new hire doesn’t need access to everything. If they do turn out fraudulent, you limit what they can reach and what they can take out.
- Connect HR + security + compliance. Especially in finance: paying a fake worker tied to a sanctioned entity is a legal risk, not just a security one.
And, crucially: no discrimination. You target fraud signals and verify identity — not nationality or the fact that someone works remotely. A defence that rejects good candidates is a failure, not a win.
Want to see how resilient your hiring and access process is to this kind of fraud? Get in touch and we start with an audit.
Frequently asked questions
What is the "fake remote worker" scheme?
People who obtain remote employment using fake or stolen identities, hiding who and where they really are. The most documented case, through FBI and US Department of Justice alerts, is North Korean IT workers: they get hired at Western companies, funnel the salary to the sanctioned regime and, in some cases, steal source code and data or extort the employer.
How do they pass hiring checks?
Because each check validates a document or a step, not the human behind it. They use forged or stolen documents, AI-generated profiles (including deepfakes), VPN and remote desktop software to appear local, payments routed through third parties or crypto, and local "facilitators" who receive the work laptop and keep access open for the operator abroad (so-called "laptop farms").
Does this mean I should suspect every remote candidate?
No. Remote work is normal and legitimate, and suspicion based on nationality is both wrong and ineffective. The right defence targets fraud signals — not people: you verify that the person in the interview is the one on the documents (liveness), control the equipment logistics, and monitor behaviour after the hire, not just at onboarding.
Why is this a bigger problem for a financial institution?
Because a fake "employee" tied to a sanctioned regime, holding legitimate credentials inside the perimeter, is simultaneously an insider risk, a data-exfiltration risk and a sanctions/compliance risk — not just an HR error. It is a case where HR, security and compliance must work together.